Official agent skill

Manage Headers

by microsoft in microsoft/power-platform-skills

Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…

OfficialMITAuto-check: notesAI & LLM Engineering

Install Manage Headers

skills CLI
$ npx skills add microsoft/power-platform-skills --skill manage-headers -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/power-platform-skills manage-headers --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/power-pages/skills/manage-headers .claude/skills/manage-headers && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
manage-headers
GitHub stars
967
Token cost
~3k tokens
SKILL.md length
1,393 words
Files
4 (incl. scripts, references)
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…

  • Works in 5 steps: Prerequisites → Inspect current headers → Assess and plan → …
  • The user wants to review headers
  • SKILL.md covers Gotchas, Workflow, Task Tracking and 1. Prerequisites, plus 6 more sections
  • Runs JavaScript scripts from its folder; calls node

What it does

Manage Headers is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related site settings. Identifies gaps and walks the user through fixes. Use when the user wants to review headers, fix CSP errors, allow embedding in another site, control cross-origin access, harden cookie settings, or asks "are my browser settings safe?", "fix my CSP", "set up CORS" — even if they only mention a specific…

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/commands.md`, `references/headers-reference.md` and `scripts/transform-headers.js`).

It sits in AI & LLM Engineering, covering Secure coding and Embeddings. The repository describes itself as: A plugin marketplace for GitHub Copilot and other AI agents that provides Power Platform development plugins, including reusable skills, agents, and commands for building and… The licence is MIT.

When your agent uses it

  • The user wants to review headers
  • Allow embedding in another site
  • Control cross-origin access
  • Harden cookie settings

Example prompts

  • “are my browser settings safe?”
  • “fix my CSP”
  • “set up CORS”
  • “/manage-headers”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Prerequisites
  2. Inspect current headers
  3. Assess and plan
  4. Apply changes
  5. Summarize

What it can do on your machine

Read from SKILL.md and the folder at commit 5ef4e4f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob
    • Grep
    • AskUserQuestion
    • TaskCreate
    • TaskUpdate
    • TaskList

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Manage Headers loads about 3k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 1,393 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from microsoft/power-platform-skills at commit 5ef4e4f, republished under its MIT licence (© microsoft). 1,393 words, ~3,023 tokens.

Download SKILL.mdSave it as .claude/skills/manage-headers/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
manage-headers
description
Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related site settings. Identifies gaps and walks the user through fixes. Use when the user wants to review headers, fix CSP errors, allow embedding in another site, control cross-origin access, harden cookie settings, or asks "are my browser settings safe?", "fix my CSP", "set up CORS" — even if they only mention a specific header name without saying "security headers".
allowed-tools
Read, Write, Edit, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList
user-invocable
true
argument-hint
[optional: --review <out-dir>]
model
opus

Plugin check: Run node "${PLUGIN_ROOT}/scripts/check-version.js" — if it outputs a message, show it to the user before proceeding.

Manage Headers

Inspect and configure the HTTP security headers for a Power Pages site. Headers are configured as HTTP/* site settings stored in .powerpages-site/site-settings/ YAML files.

Initial request: $ARGUMENTS

Gotchas

  • Site settings are YAML files. Each header is a separate .yml file in .powerpages-site/site-settings/. The file name uses - instead of / (e.g., HTTP/X-Frame-Options → http-x-frame-options.sitesetting.yml).
  • Absent = no header. When a site setting is absent, the runtime omits that header entirely (except CSP on new sites — see headers-reference.md).
  • HSTS and Cache-Control are platform-managed. Do not try to set HTTP/Strict-Transport-Security — the runtime does not recognize it and the setting has no effect.
  • Maker-mode bypasses headers. Requests from Power Pages Studio skip all HTTP/* header emission. Verify headers in an incognito tab, not the studio preview.
  • CSP is pass-through. The runtime emits the value verbatim — it does NOT merge runtime sources automatically. The CSP MUST include Power Pages runtime hosts or the site breaks.
  • CSP nonce. When script-src contains 'nonce', the runtime replaces it per-request with 'nonce-<random>' and auto-hashes inline event handlers. Scripts created dynamically via document.createElement do NOT receive the nonce.
  • SameSite=None requires HTTPS. The runtime sets Secure on every cookie over HTTPS automatically.
  • CORS * is auto-specialized. The runtime replaces * per-request with the specific requesting Origin — the browser sees a single-origin header, not a wildcard.

Workflow

  1. Prerequisites — Locate project, confirm site-settings directory exists
  2. Inspect current headers — Read site-setting YAML files, identify configured and missing headers
  3. Assess and plan — Identify gaps, present recommendations
  4. Apply changes — Edit existing settings or create new ones
  5. Summarize — Present results, record usage, offer follow-ups

Task Tracking

Create tasks in four groups. Mark each in_progress when starting, completed when done.

GroupWhen to createTasks
1At startCheck prerequisites
2After prerequisites passInspect current headers · Assess and plan (skip "Assess and plan" in review mode)
3After user approves changesApply changes (skip in review mode OR if no changes were accepted)
4After apply or assessSummarize (always)

1. Prerequisites

1.1 Locate the project, detect review mode

Use Glob to find **/powerpages.config.json. If $ARGUMENTS contains --review <out-dir>, remember the output directory — Steps 3–4 are skipped and Step 5 writes JSON only.

1.2 Verify site-settings directory

Check that .powerpages-site/site-settings/ exists. If not, the site has not been deployed yet — tell the user and recommend /deploy-site. Stop.


2. Inspect current headers

Use Glob to find all *.yml files in .powerpages-site/site-settings/. Use Read to read each file and extract the name and value fields. Identify all settings with an HTTP/ prefix — these are the configured headers.

Compare against the recognized header catalogue in references/headers-reference.md. For each header in the catalogue:

  • Present — record its current value.
  • Missing — record it as absent and note the recommended value from headers-reference.md.

For CSP specifically: if HTTP/Content-Security-Policy is present, scan the project's source files using Glob + Read to find external URLs and check whether they are covered by the policy. Identify the site's cloud environment via pac auth who to determine the correct Power Pages runtime host (see headers-reference.md § "Power-Pages-runtime sources a CSP must allow").


3. Assess and plan

Skip in review mode.

MUST use plain language only. Never lead with words like CSP, CORS, HSTS, or MIME sniffing — explain using everyday language:

Header conceptPlain-language name
Content-Security-Policy"which scripts and resources the browser is allowed to load"
X-Frame-Options / frame-ancestors"whether other websites can put your site inside a frame"
X-Content-Type-Options"stop the browser from guessing file types"
CORS headers"which other websites can call your site's data"
SameSite cookies"when the browser sends your sign-in cookie"
Default approach

Read references/headers-reference.md for recommended values and guidance. Present the most important gaps first — headers that are missing or misconfigured relative to the recommended values.

<!-- gate: manage-headers:3.per-finding | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · manage-headers:3.per-finding): Per-finding loop — for each header gap, prompt accept / customize / skip. Fires PER FINDING in the loop; skipped findings leave the header at its current value, accepted/customized findings get an Edit / create-script call in Phase 4.

Trigger: Phase 3 entry has tallied header gaps against references/headers-reference.md. Why we ask: Auto-accepting can apply CSP/CORS values that break the site (legitimate scripts blocked, third-party widgets refused); auto-skipping leaves the site missing important headers. Cancel leaves: Nothing — Phase 4's Edit / create-script call only fires on accepted findings.

For each finding, present via AskUserQuestion:

  • A plain-language explanation of why the change matters
  • The recommended value
  • Options: accept the recommendation, customize, or skip

Do NOT present all headers at once — present the important gaps first. For headers already set to recommended values, mention them in the summary without requiring action.

CSP composition

When the user needs a CSP (missing or incomplete), compose one using:

  1. The starter template from headers-reference.md
  2. The correct cloud-specific runtime host
  3. External URLs discovered from the project's source files — scan ALL source files, templates, scripts, etc.
  4. The 'nonce' keyword for inline scripts

When reviewing an existing CSP, validate:

  • All external URLs actually loaded by the site are covered in the policy
  • Runtime hosts are included for the site's cloud

Present the composed or corrected CSP for review. Recommend starting in report-only mode (HTTP/Content-Security-Policy-Report-Only) before enforcing.


Show full SKILL.md (535 more words)Show less

4. Apply changes

Skip in review mode.

For existing settings: use Edit on the YAML file directly — change the value field.

For new settings: use the shared create script:

bash
node "${PLUGIN_ROOT}/scripts/create-site-setting.js" \
  --projectRoot "<PROJECT_ROOT>" \
  --name "<setting-name>" \
  --value "<value>" \
  --description "<description>"

See references/commands.md for details.

After all changes are applied, offer to deploy: "Ready to deploy these changes? They take effect after the next deploy." If yes, invoke /deploy-site.


5. Summarize

5.1 Review mode

First, read the configured HTTP/* site settings (from Step 2 — you already have them). Then write <REVIEW_DIR>/header-annotations.json with a plain-language description for each header and, when the configured value has a genuine issue (missing critical directive, weak value), a suggested fix. The transform script no longer hardcodes header descriptions — they come from you.

json
{
  "headers": {
    "HTTP/<HeaderName>": { "description": "What this header does, in plain language.", "fix": "Optional fix if the configured value has a genuine issue." }
  }
}

Use references/headers-reference.md for authoritative descriptions and validation rules. Surface a fix only when the value has a real problem — do not editorialize on every header.

Then run the transform:

bash
node "${PLUGIN_ROOT}/skills/manage-headers/scripts/transform-headers.js" \
  --projectRoot "<PROJECT_ROOT>" \
  --annotations "<REVIEW_DIR>/header-annotations.json"

Write the stdout to <REVIEW_DIR>/manage-headers.json and stop. The transform emits { status, findings, details }; the orchestrating skill handles presentation.

5.2 Present summary

Skip in review mode.

Plain-language summary: what was changed, what gaps remain, and what is already well-configured.

5.3 Record skill usage

Reference: ${PLUGIN_ROOT}/references/skill-tracking-reference.md

Use --skillName "ManageHeaders".

5.4 Offer follow-ups

If a natural follow-up exists based on findings, suggest it. If no meaningful follow-up exists, end the skill.


Constraints

  • Plain language — MUST NOT use technical jargon with the user. Explain header names using everyday language.
  • headers-reference.md is the source of truth — recommended values and the recognized header catalogue live there. Read it before assessing.
  • Context-aware interactions — every recommendation MUST reflect the site's actual configuration and usage:
    • Read the site's source files, integrations, and auth setup before recommending any value.
    • Never recommend a value without verifying it will not break the site's functionality (see the "Context to verify" column in headers-reference.md).
    • Acknowledge existing values when proposing changes — they may be intentional.
    • For CSP, reference actual external URLs found in the project's source files.
    • For CORS, verify the site's actual cross-origin consumers before scoping.
    • For Cross-Origin-Opener-Policy, verify whether the site uses popup-based auth.
    • For Cross-Origin-Resource-Policy, verify whether the site hosts Azure AD B2C custom login pages, is embedded cross-origin, or has integrations that load its resources. Leave absent or use cross-origin when unsure.
  • Preview is for change review only — include preview only on options that modify a setting value. Do not add to informational choices.
  • Recommendations MUST NOT break the site — before recommending a value, consider whether it would block resources the site actually uses. For CSP, always verify that runtime sources and project external URLs are included. For CORS, verify the site's actual cross-origin needs. When unsure, recommend report-only mode first.
  • NEVER recommend broadening an existing policy — if the user already has a tight CSP, CORS scope, or restrictive header value, do not suggest making it less restrictive. A working tight policy is better than a broad one. Never recommend https: wildcards in CSP directives — list specific hosts instead.
  • Deploy after changes — header changes only take effect after deploying. Always offer /deploy-site after applying changes.

References

  • references/headers-reference.md — recognized header catalogue, recommended values, CSP composition rules, runtime sources. Read before Step 2 (inspect) and Step 3 (assess) in interactive mode.
  • references/commands.md — shared create-site-setting.js usage. Read at Step 4 (apply) when creating new settings.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in plugins/power-pages/skills/manage-headers of microsoft/power-platform-skills.

  • SKILL.md
  • references/commands.md
  • references/headers-reference.md
  • scripts/transform-headers.js

Open the folder on GitHubat commit 5ef4e4f

Compare with similar skills

Manage Headers next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Manage Headers compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Manage Headers this skillmicrosoft/power-platform-skills967—~3kAutomated safety check: NotesMIT
Hunt RAG Vectorelementalsouls/Claude-BugHunter4.8k—~2.6kAutomated safety check: PassMIT
Chroma Vector DatabaseOrchestra-Research/AI-Research-SKILLs13k8 repos~2.3kAutomated safety check: PassMIT
CLIP Image-Text MatchingOrchestra-Research/AI-Research-SKILLs13k8 repos~1.7kAutomated safety check: PassMIT
SageMaker Serving Image Selectionhuggingface/skills11k1 repos~4.6kAutomated safety check: PassApache-2.0
Codebase Managementgiancarloerra/SocratiCode3.3k1 repos~1.8kAutomated safety check: PassAGPL-3.0

Similar skills

  • Hunt RAG Vector

    elementalsouls/Claude-BugHunter

    Hunt vector-store / embedding-layer weaknesses in RAG pipelines (OWASP LLM08 Vector and Embedding Weaknesses) — persistent corpus poisoning that survives across sessions and users (distinct from…

    4.8k GitHub stars~2.6k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Chroma Vector Database

    Orchestra-Research/AI-Research-SKILLs

    Shows how to store documents and embeddings in Chroma, query them by similarity with metadata filters, and persist them to disk for RAG and semantic search projects.

    13k GitHub starsUsed in 8 repos~2.3k tokens
    AI & LLM EngineeringAuto-check passed
  • CLIP Image-Text Matching

    Orchestra-Research/AI-Research-SKILLs

    Explains OpenAI's CLIP model for zero-shot image classification, image-text similarity, semantic image search and content moderation, with install steps and code patterns.

    13k GitHub starsUsed in 8 repos~1.7k tokens
    AI & LLM EngineeringAuto-check passed
  • Official

    Chooses the right serving container and current image URI for deploying a Hugging Face model to a SageMaker endpoint, preferring Hugging Face images over generic ones.

    11k GitHub starsUsed in 1 repo~4.6k tokens
    AI & LLM EngineeringAuto-check passed
  • Codebase Management

    giancarloerra/SocratiCode

    Set up, index, and manage SocratiCode codebase indexing. An agent skill from giancarloerra/SocratiCode.

    3.3k GitHub starsUsed in 1 repo~1.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Official

    Routes a sentence-transformers training task to the right model type and required reference docs and example scripts, covering bi-encoders, rerankers, sparse and multi-vector models.

    11k GitHub starsUsed in 1 repo~2.6k tokens
    AI & LLM EngineeringAuto-check passed

More from microsoft/power-platform-skills

All 87 skills in this repo
  • Manage Firewall

    microsoft/power-platform-skills

    Official

    Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.

    967 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Scan Code

    microsoft/power-platform-skills

    Official

    Scans a Power Pages site project for security issues in source code and dependencies.

    967 GitHub stars~3.4k tokensUpdated today
    Auto-check: notes
  • Scan Site

    microsoft/power-platform-skills

    Official

    Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

    967 GitHub stars~3.2k tokensUpdated today
    Auto-check: notes
  • Setup Datamodel

    microsoft/power-platform-skills

    Official

    Creates Dataverse tables, columns, and relationships for a Power Pages site based on a data model proposal.

    967 GitHub stars~4k tokensUpdated today
    Auto-check: notes
  • Add Server Logic

    microsoft/power-platform-skills

    Official

    Creates, edits, and manages Power Pages Server Logic files — server-side JavaScript that runs securely on the Power Pages runtime.

    967 GitHub stars~18k tokensUpdated today
    Auto-check: notes
  • Activate Site

    microsoft/power-platform-skills

    Official

    Activates and provisions a Power Pages website in a Power Platform environment via the Power Platform REST API.

    967 GitHub starsUsed in 1 repo~5k tokens
    Auto-check: notes

Questions about Manage Headers

What does Manage Headers do?

Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…. Manage Headers is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related site settings.

When should I use Manage Headers?

Manage Headers fits situations like: the user wants to review headers; allow embedding in another site; control cross-origin access; harden cookie settings.

How do I install Manage Headers in Claude Code?

Run `npx skills add microsoft/power-platform-skills --skill manage-headers -a claude-code`. Or copy the skill folder (plugins/power-pages/skills/manage-headers in microsoft/power-platform-skills) into .claude/skills/manage-headers in your project. Claude Code loads it when a task matches its description.

How do I install Manage Headers in Codex?

Run `npx skills add microsoft/power-platform-skills --skill manage-headers -a codex`. Or copy the skill folder (plugins/power-pages/skills/manage-headers in microsoft/power-platform-skills) into .agents/skills/manage-headers in your project. Codex loads it when a task matches its description.

Can I use Manage Headers in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/power-platform-skills --skill manage-headers -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-headers, .gemini/skills/manage-headers, .github/skills/manage-headers and .opencode/skills/manage-headers in your project.

What does Manage Headers need to run?

Going by SKILL.md and its folder, Manage Headers needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList.

Does Manage Headers access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Manage Headers safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Manage Headers use?

Manage Headers is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Manage Headers use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.1k tokens, read only when the agent opens those files.

What are the alternatives to Manage Headers?

Skills that share tags, products or a category with Manage Headers: Hunt RAG Vector (elementalsouls/Claude-BugHunter, 4.8k stars), Chroma Vector Database (Orchestra-Research/AI-Research-SKILLs, 13k stars), CLIP Image-Text Matching (Orchestra-Research/AI-Research-SKILLs, 13k stars) and SageMaker Serving Image Selection (huggingface/skills, 11k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Manage Headers?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/power-platform-skills, which has 967 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/power-platform-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.